2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7284 | — | — | 2.8% | Apr 29, 2014 | The PlRPC module, possibly 0.2020 and earlier, for Perl uses the Storable module, which allows remote attackers to execu... |
| CVE-2013-7273 | — | — | 0.4% | Apr 29, 2014 | GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a deni... |
| CVE-2013-7259 | — | — | 1.3% | Apr 29, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentic... |
| CVE-2013-7236 | — | — | 1.5% | Apr 29, 2014 | Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unic... |
| CVE-2013-7235 | — | — | 1.5% | Apr 29, 2014 | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users vi... |
| CVE-2013-7234 | — | — | 1.2% | Apr 29, 2014 | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks v... |
| CVE-2013-7221 | — | — | 0.4% | Apr 29, 2014 | The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Ent... |
| CVE-2013-7220 | — | — | 0.4% | Apr 29, 2014 | js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbit... |
| CVE-2013-7134 | — | — | 2.3% | Apr 29, 2014 | Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by levera... |
| CVE-2013-7111 | — | — | 1.5% | Apr 29, 2014 | The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 ... |
| CVE-2013-7068 | — | — | 1.0% | Apr 29, 2014 | The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restr... |
| CVE-2013-7066 | — | — | 1.1% | Apr 29, 2014 | The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles b... |
| CVE-2013-7065 | — | — | 1.2% | Apr 29, 2014 | The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions a... |
| CVE-2013-7064 | — | — | 0.9% | Apr 29, 2014 | Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows re... |
| CVE-2013-7063 | — | — | 1.4% | Apr 29, 2014 | The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain se... |
| CVE-2013-4285 | — | — | 0.3% | Apr 28, 2014 | A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local user... |
| CVE-2013-6053 | — | — | 2.2% | Apr 27, 2014 | OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based... |
| CVE-2013-4336 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5964. Reason: This candidate is a duplicate of C... |
| CVE-2013-0296 | — | — | 0.3% | Apr 27, 2014 | Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that ... |
| CVE-2013-6887 | — | — | 2.2% | Apr 27, 2014 | OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer de... |
| CVE-2013-4337 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5965. Reason: This candidate is a duplicate of... |
| CVE-2013-4145 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3414. Reason: This candidate is a duplicate of... |
| CVE-2013-5660 | — | — | 11.2% | Apr 25, 2014 | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip f... |
| CVE-2013-4726 | — | — | 1.1% | Apr 25, 2014 | Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1... |
| CVE-2013-4723 | — | — | 2.0% | Apr 25, 2014 | Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly o... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now